In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70,
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H약점 (CWE)
- CWE-918
서버측 요청 위조(SSRF) — 서버가 공격자가 지정한 내부 자원에 요청하도록 강제.
상세 설명
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (REST) API using a system-level session token and modify the Splunk platform configuration. The user could then obtain a session token without a password and use it to access all relevant data and affect system integrity. The vulnerability is possible because Splunk Secure Gateway does not validate decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
영향받는 제품·버전
- splunk splunk9.4.0 - 9.4.14other
- splunk splunk10.0.0 - 10.0.9other
- splunk splunk10.2.0 - 10.2.6other
- splunk splunk10.4.0 - 10.4.2other
- splunk splunk_secure_gateway3.8.0 - 3.8.70other
- splunk splunk_secure_gateway3.9.0 - 3.9.23other
- splunk splunk_secure_gateway3.10.0 - 3.10.9other
영향받는 구성 (CPE) 2
- splunk splunk≥ 9.4.0 < 9.4.14cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
- splunk splunk_secure_gateway≥ 3.8.0 < 3.8.70cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
참고 자료 1
- https://advisory.splunk.com/advisories/SVD-2026-0801Vendor Advisory
링크 내용 불러오는 중…